Adobe Acrobat vulnerabilities

1,356 known vulnerabilities affecting adobe/acrobat.

Total CVEs
1,356
CISA KEV
23
actively exploited
Public exploits
43
Exploited in wild
27
Severity breakdown
CRITICAL540HIGH476MEDIUM316LOW24

Vulnerabilities

Page 67 of 68
CVE-2009-1492CRITICALCVSS 9.3PoC≥ 7.0, ≤ 7.1.1≥ 8.0, ≤ 8.1.4+1 more2009-04-30
CVE-2009-1492 [CRITICAL] CWE-399 CVE-2009-1492: The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and ea The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments
nvd
CVE-2009-1062CRITICALCVSS 9.3≤ 9.0v7.0+17 more2009-03-25
CVE-2009-1062 [CRITICAL] CVE-2009-1062: Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers t Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to trigger memory corruption and possibly execute arbitrary code via unknown attack vectors related to JBIG2, a different vulnerability than CVE-2009-0193 and CVE-2009-1061.
nvd
CVE-2009-0928CRITICALCVSS 10.0≤ 9.0v3.0+45 more2009-03-25
CVE-2009-0928 [CRITICAL] CWE-119 CVE-2009-0928: Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecified table.
nvd
CVE-2009-0658HIGHCVSS 7.8ExploitedPoC≥ 7.0, ≤ 7.1.1≥ 8.0, ≤ 8.1.4+1 more2009-02-20
CVE-2009-0658 [HIGH] CWE-119 CVE-2009-0658: Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attacker Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.
nvd
CVE-2008-5331HIGHCVSS 7.5v9v9.02008-12-05
CVE-2008-5331 [HIGH] CWE-310 CVE-2008-5331: Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for att Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute-force attack.
nvd
CVE-2008-4814CRITICALCVSS 9.3≤ 8.1.2v8.1.12008-11-05
CVE-2008-4814 [CRITICAL] CWE-20 CVE-2008-4814: Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allows remote attackers to execute arbitrary code via unknown vectors, related to an "input validation issue."
nvd
CVE-2008-4813CRITICALCVSS 9.3≤ 8.1.2v8.1.12008-11-05
CVE-2008-4813 [CRITICAL] CWE-399 CVE-2008-4813: Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allow remote attackers to execute arbi Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allow remote attackers to execute arbitrary code via a crafted PDF document that (1) performs unspecified actions on a Collab object that trigger memory corruption, related to a GetCosObj method; or (2) contains a malformed PDF object that triggers memory corruption during parsing.
nvd
CVE-2008-4817CRITICALCVSS 9.3≤ 8.1.2v8.1.12008-11-05
CVE-2008-4817 [CRITICAL] CWE-20 CVE-2008-4817: The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attack The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.
nvd
CVE-2008-4812CRITICALCVSS 9.3≤ 8.1.2v8.1.12008-11-05
CVE-2008-4812 [CRITICAL] CWE-20 CVE-2008-4812: Array index error in Adobe Reader and Acrobat, and the Explorer extension (aka AcroRd32Info), 8.1.2, Array index error in Adobe Reader and Acrobat, and the Explorer extension (aka AcroRd32Info), 8.1.2, 8.1.1, and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that triggers an out-of-bounds write, related to parsing of Type 1 fonts.
nvd
CVE-2008-4815HIGHCVSS 7.5≤ 8.1.2v8.1.12008-11-05
CVE-2008-4815 [HIGH] CWE-264 CVE-2008-4815: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.
nvd
CVE-2008-4816MEDIUMCVSS 4.3≤ 8.1.2v8.1.12008-11-05
CVE-2008-4816 [MEDIUM] CVE-2008-4816: Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allow Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.
nvd
CVE-2008-2992HIGHCVSS 7.8KEVPoC≤ 8.1.22008-11-04
CVE-2008-2992 [HIGH] CVE-2008-2992: Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
nvd
CVE-2008-4071MEDIUMCVSS 5.0PoCv92008-09-15
CVE-2008-4071 [MEDIUM] CWE-20 CVE-2008-4071: A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Ex A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.
nvd
CVE-2008-2042CRITICALCVSS 9.3≤ 8.1.1v3.0+33 more2008-05-08
CVE-2008-2042 [CRITICAL] CWE-20 CVE-2008-2042: The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.
nvd
CVE-2008-0726CRITICALCVSS 9.3≤ 8.1.12008-02-12
CVE-2008-0726 [CRITICAL] CWE-189 CVE-2008-0726: Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute ar Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption.
nvd
CVE-2007-5663CRITICALCVSS 9.3≤ 8.1.12008-02-12
CVE-2007-5663 [CRITICAL] CWE-94 CVE-2007-5663: Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a c Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655.
nvd
CVE-2007-5659HIGHCVSS 7.8KEVPoCfixed in 8.1.22008-02-12
CVE-2007-5659 [HIGH] CWE-120 CVE-2007-5659: Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to ex Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
nvd
CVE-2007-5666MEDIUMCVSS 6.2≤ 8.1.12008-02-12
CVE-2007-5666 [MEDIUM] CWE-94 CVE-2007-5666: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
nvd
CVE-2008-0655CRITICALCVSS 9.8KEVfixed in 8.1.22008-02-07
CVE-2008-0655 [CRITICAL] CWE-200 CVE-2008-0655: Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact an Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
nvd
CVE-2007-5020CRITICALCVSS 9.3v8.12007-09-21
CVE-2007-5020 [CRITICAL] CWE-94 CVE-2007-5020: Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to exec Unspecified vulnerability in Adobe Acrobat and Reader 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted PDF file, related to the mailto: option and Internet Explorer 7 on Windows XP. NOTE: this information is based upon a vague pre-advisory by a reliable researcher.
nvd